smss wink32.sys rootkit or not?

Discussion in 'Ghost Security Suite (GSS)' started by SystemJunkie, Mar 23, 2006.

Thread Status:
Not open for further replies.
  1. f3x

    f3x Registered Member

    Joined:
    Feb 6, 2006
    Posts:
    311
    Location:
    Montreal, Quebec
    I use appdefend and Icesword together without any problem ... What is your version... how do you know it's appdefend fault ?



    Well.. to me you have only one major problem
    You can't choose between the security products and you install to much thing at the same time... try limiting yourself to non overlaping program ... ideally less than 3 realtime.


    However this strange mixture of problem have made some great things
    I think it's the first time Gavin post in Ghost security forum.
     
  2. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Your theory is too simple.

    On earth are million pcs with million of different configs it´s not only the mass of software. I tested it. If I stopped the sysdriver of gss, IceSword worked without problems.
     
  3. gottadoit

    gottadoit Security Expert

    Joined:
    Jul 12, 2004
    Posts:
    605
    Location:
    Australia
    SystemJunkie,
    Did you get a minidump or memory dump when you had your BSOD ?

    You should check and then email support at ghostsecurity.com with a problem report and see if Jason wants you to collect any information about the problem. It might be that he just suggests that you wait until the next beta to see if the problem changes or goes away.

    Its worth asking (via email) because giving additional feedback helps to make the application better and to help cope with the many and varied circumstances out there.
     
  4. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    I am not sure if those people have still time for such things, programming is the most time consuming thing, and if they would need info they could visit this thread and ask for more informations.

    Look some more strange things, AppDefend is probably right when it says Rootkit.

    http://i2.tinypic.com/szxzlz.png

    Does this look normal? What about that?

    http://i2.tinypic.com/szy0bt.png

    Smss.exe seems to play an important role in the game of antihooking tools.
    Beside Process Guard told me the same, that Antihook wants to kill smss.exe.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.